CVE-2019-1748 describes a certificate validation vulnerability in the Cisco Network Plug-and-Play (PnP) agent within Cisco IOS and IOS XE Software. An unauthenticated, remote attacker can exploit this by supplying a crafted certificate, enabling man-in-the-middle attacks to decrypt and modify sensitive data. With a CVSS score of 7.4 (High), this vulnerability has a network attack vector and high impact on confidentiality and integrity, despite high attack complexity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.0\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.0\(1\):*:*:*:*:*:*:* | ||
12.0\(1\)tCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.0\(1\)t:*:*:*:*:*:*:* | ||
12.0\(1\)t1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.0\(1\)t1:*:*:*:*:*:*:* | ||
12.0\(1\)xeCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.0\(1\)xe:*:*:*:*:*:*:* | ||
12.0\(1a\)CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.0\(1a\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.